Complaints Procedure | Simman Solicitors
📍 Croydon: 83 South End, CR0 1BG📍 Hayes: Machine Works, 5 Pressing Ln, UB3 1FD
📞 020 8686 1085  ✉ legal@simmansolicitors.org.uk
Mon–Fri 9am–5pm  ·  Saturday: By Appointment  ·  ☎ 020 8686 1085
Data Protection

Privacy & GDPR Policy

How Simman Solicitors collects, uses, stores, and protects your personal data — in full compliance with UK GDPR and the Data Protection Act 2018.

Last updated: January 2024  ·  Reviewed annually

⚖️  Simman Solicitors is authorised and regulated by the Solicitors Regulation Authority (SRA ID: 342119 / Branch ID: 8014732). We are registered as a Data Controller with the Information Commissioner's Office (ICO). We take your privacy and data protection rights extremely seriously.

1. Who We Are

Simman Solicitors ("the Firm", "we", "us", "our") is a solicitors' firm with offices at:

  • Head Office: 83 South End, Croydon, CR0 1BG
  • Branch Office: Machine Works, 5 Pressing Lane, Hayes, UB3 1FD

We act as the Data Controller for all personal data processed in connection with the provision of legal services. For data protection queries, contact us at legal@simmansolicitors.org.uk or call 020 8686 1085.

2. What Personal Data We Collect

We collect and process the following categories of personal data:

  • Identity data: full name, date of birth, nationality, gender, passport and identity document details
  • Contact data: address, email address, telephone numbers
  • Immigration and legal data: visa status, Home Office reference numbers, immigration history, case documents, tribunal decisions
  • Financial data: information required to assess Legal Aid eligibility (income, assets, benefits)
  • Special category data: where relevant to your case — health information, ethnicity, religion, criminal convictions, political opinions
  • Family and relationship data: details of family members, dependants, relationships relevant to your case
  • Third party data: details of social workers, foster carers, interpreters, or other parties involved in your matter

We only collect data that is necessary and proportionate for the purpose of providing you with legal services.

3. How We Collect Your Data

  • Directly from you — in person, by telephone, by email, or via our website forms
  • From third parties — the Home Office, courts and tribunals, other solicitors, social workers, interpreters, and medical experts
  • From public sources — court records, Home Office databases, and official registers where lawfully accessible

4. Legal Basis for Processing

We rely on the following legal bases under UK GDPR Article 6:

Legal BasisWhen We Use It
Contract performanceProcessing necessary to provide the legal services you have instructed us to carry out
Legal obligationRegulatory compliance with SRA, Legal Aid Agency, HMRC, and anti-money laundering requirements
Legitimate interestsRunning and improving our practice, managing client relationships, preventing fraud
ConsentWhere we send you marketing or contact you for non-case purposes (you may withdraw at any time)

For special category data (Article 9), we rely on the basis of legal claims — processing is necessary for the establishment, exercise, or defence of legal claims on your behalf.

5. How We Use Your Data

  • Providing immigration, asylum, family law, and other legal services to you
  • Assessing your eligibility for Legal Aid funded services
  • Communicating with you about your case, appointments, and matters
  • Complying with our regulatory obligations to the SRA and Legal Aid Agency
  • Anti-money laundering and identity verification checks
  • Managing our accounts and records
  • Improving our services and training our staff

We will never sell your personal data to third parties, nor use it for unsolicited marketing without your explicit consent.

6. Who We Share Your Data With

We may share your data with the following parties where necessary for your case or required by law:

  • The Home Office — in the course of immigration and asylum proceedings
  • Courts and Tribunals — First-tier Tribunal, Upper Tribunal, Court of Appeal
  • The Legal Aid Agency (LAA) — to process Legal Aid applications and billing
  • Expert witnesses — medical experts, country experts, interpreters
  • Barristers and Counsel — where we instruct Counsel on your behalf
  • Social workers and local authorities — where relevant to your matter
  • The SRA — as required by our regulatory obligations
  • HMRC — for tax and anti-money laundering compliance

All third parties we share data with are required to handle it lawfully and in accordance with data protection law.

7. Data Retention — In Line with LAA Requirements

📁  In accordance with Legal Aid Agency (LAA) requirements and SRA guidelines, we retain all client files and associated personal data for a period of 6 years after the closure of your file. After this period, files and data are securely and permanently destroyed in accordance with our Data Destruction Policy.

Type of RecordRetention PeriodBasis
Client matter files (Legal Aid)6 years after file closureLAA contractual requirement & SRA guidelines
Client matter files (Private)6 years after file closureSRA guidelines & limitation periods
Financial and billing records7 yearsHMRC / Companies Act requirements
Anti-money laundering records5 yearsMoney Laundering Regulations 2017
Will and property documentsIndefinitely or as instructedClient instructions
Website enquiry data12 monthsLegitimate interests

When retention periods expire, data is destroyed securely — paper records are shredded, and electronic records are permanently deleted. Destruction is logged and recorded.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or disclosure. These include:

  • Secure case management systems with access controls
  • Encrypted email communications for sensitive matters
  • Restricted access — only staff who need data to do their job can access it
  • Locked storage for physical files
  • Regular staff training on data protection obligations
  • Secure disposal of paper and electronic records

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you without undue delay.

9. International Transfers

Where your matter requires us to share data internationally (for example, with embassies, overseas courts, or country experts), we will only do so where lawful safeguards are in place. We will inform you of any such transfer where appropriate.

10. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

RightWhat This Means
Right of accessRequest a copy of the personal data we hold about you (Subject Access Request)
Right to rectificationAsk us to correct inaccurate or incomplete data
Right to erasureAsk us to delete your data in certain circumstances (note: this may not apply where we have legal obligations to retain it)
Right to restrict processingAsk us to limit how we use your data in certain circumstances
Right to data portabilityReceive your data in a portable format where technically feasible
Right to objectObject to processing based on legitimate interests
Rights re: automated decisionsWe do not make solely automated decisions about you

To exercise any of these rights, contact us at legal@simmansolicitors.org.uk. We will respond within one calendar month.

11. Complaints to the ICO

If you believe we have not handled your personal data correctly, you have the right to complain to the Information Commissioner's Office (ICO):

We would however ask that you contact us first so we can try to resolve any concerns directly.

12. Changes to This Policy

We review and update this policy at least annually or whenever there is a significant change in law or our practices. The current version is always available on our website. Continued use of our services after any update constitutes acceptance of the revised policy.